We’re facing a serious compliance issue with our HubSpot hs-2022 instance. Our loyalty program module is supposed to automatically delete customer data after 24 months of inactivity per our data retention policy, but it’s not happening. We’ve configured the automation workflows to trigger deletion, but records are still sitting in the system well beyond the retention period.
Here’s our current workflow setup:
Workflow: Loyalty Data Cleanup
Trigger: Last Activity Date > 730 days
Action: Delete contact record
Status: Active (but not executing)
This is creating significant compliance risks, especially with GDPR requirements. Has anyone successfully implemented automated data retention in the loyalty programs module for hs-2022?
Here’s the complete solution addressing all three critical areas - data retention policy configuration, automation workflows, and compliance requirements:
1. Data Retention Policy Setup:
First, abandon the workflow approach entirely. In hs-2022, use the dedicated Data Retention feature:
Navigate to Settings > Security & Privacy > Data Retention Policies
Click ‘Create Policy’ and name it ‘Loyalty Program Inactive Members’
Set retention period to 730 days (24 months)
Configure the policy to run weekly on Sundays at 2 AM (low traffic period)
2. Automation Workflows - Correct Implementation:
Workflows can’t delete records, but they can prepare them for deletion:
// Pseudocode - Preparation workflow:
1. Create workflow: 'Flag Inactive Loyalty Members'
2. Trigger: Contact property 'Last Activity Date' > 700 days
3. Action: Set 'Pending Deletion' property = True
4. Action: Set 'Deletion Eligible Date' = Today + 30 days
5. Send notification to compliance team for review
This 30-day buffer allows manual review before automated deletion.
3. Compliance Requirements:
To meet GDPR and compliance standards:
Target List Creation:
Go to Contacts > Lists > Create Active List
Name: ‘Loyalty Inactive - Retention Policy’
Filters: ‘Loyalty Program Member’ = ‘Yes’ AND ‘Last Activity Date’ > 730 days AND ‘Pending Deletion’ = ‘True’
Link this list to your retention policy
Role-Based Access Configuration:
Settings > Users & Teams > [Your Service Account]
Enable ‘Data Deletion’ permission (requires Super Admin)
Enable ‘Audit Log Access’ for compliance tracking
Audit Trail Setup:
Settings > Data Management > Audit Logs
Enable ‘Contact Deletion Logging’
Configure monthly export to secure storage
Set up email alerts for deletion events to compliance team
Critical Configuration Setting:
In hs-2022, there’s a hidden setting that blocks automated deletions by default. Go to Settings > Data Management > Data Protection and uncheck ‘Require Manual Approval for All Deletions’. Replace it with ‘Require Approval for Bulk Deletions (>100 records)’ to maintain safety while allowing policy execution.
Testing Protocol:
Before going live:
Create test contacts with backdated ‘Last Activity Date’
Tag them with ‘TEST_RETENTION’ property
Run retention policy in ‘Preview Mode’ first
Verify only test records are targeted
Execute and confirm deletion within 24 hours
Review audit logs for complete record of action
This approach has successfully resolved retention policy issues for multiple EU-based clients facing GDPR compliance requirements in hs-2022.
This draft is based on general HubSpot knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.
I’ve seen this issue before. The problem is that HubSpot’s automation workflows don’t actually have permission to delete contact records by default in hs-2022. You need to enable a specific data governance setting in the admin panel first. Check Settings > Data Management > Data Retention and make sure ‘Allow Workflow Deletions’ is enabled.
The automation workflow approach won’t work reliably for data retention because HubSpot prioritizes data preservation over automated deletion. Instead, you should use the Data Retention Policy feature that was introduced in hs-2022. It’s specifically designed for compliance scenarios and bypasses the workflow limitations. Navigate to Settings > Security & Privacy > Data Retention Policies to configure it properly.
I found the Data Retention Policies section, but when I try to create a policy for loyalty program contacts, it only shows options for marketing contacts and deals. There’s no specific option for loyalty program members. How do I target those specific records?
Loyalty program contacts in hs-2022 are actually stored as regular contacts with a specific property flag. You need to create a custom list first that filters contacts where ‘Loyalty Program Member’ equals ‘Yes’ and ‘Last Activity Date’ is older than 730 days. Then, in your data retention policy, target that specific list. This ensures only inactive loyalty members are affected by the retention policy while preserving active customer data.
There’s an additional layer you need to consider - role-based access controls. Even if you configure the retention policy correctly, it won’t execute unless your HubSpot user account has ‘Data Deletion’ permissions at the Super Admin level. This is a security feature in hs-2022 to prevent accidental mass deletions. Have your HubSpot admin verify that the service account running these policies has the appropriate permissions. Also, ensure you’ve configured audit logging to track all deletions for compliance reporting.